Multiple Vulnerabilities in Cisco Catalyst SD-WAN Software
7 August 2026
Attackers can exploit multiple vulnerabilities in Cisco Catalyst SD-WAN Software to bypass security controls, gain unauthorised access, access or manipulate files, and disclose sensitive information. Patch immediately.
Background
Cisco has released security updates to address multiple vulnerabilities (CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, & CVE-2026-20313) affecting Cisco Catalyst SD-WAN Software.
The vulnerabilities have Common Vulnerability Scoring System (CVSS v3.1) scores of: CVE-2026-20303, CVE-2026-20304 and CVE-2026-20310 at 9.9, CVE-2026-20312 at 8.8, and CVE-2026-20313 at 7.7 out of 10.
Impact
Successful exploitation of these vulnerabilities could lead to the following:
CVE-2026-20303 (CVSS 9.9): An improper input validation vulnerability could allow an attacker to exploit input validation, path traversal or external path control weaknesses in an affected system.
CVE-2026-20304 (CVSS 9.9): An improper access control vulnerability could allow an attacker to bypass authentication or authorisation controls or gain unauthorised privileges on an affected system.
CVE-2026-20310 (CVSS 9.9): An improper link resolution before file access vulnerability could allow an attacker to improperly access files on an affected system.
CVE-2026-20312 (CVSS 8.8): A cleartext storage of sensitive information vulnerability could allow an attacker to obtain sensitive information stored in cleartext on an affected system.
CVE-2026-20313 (CVSS 7.7): An improper validation of specified quantity in input vulnerability could allow an attacker to submit improperly validated data to an affected system, potentially affecting its intended operation.
Affected Products
The vulnerabilities affect the following products:
Cisco Catalyst SD-WAN Software releases earlier than 20.9
Cisco Catalyst SD-WAN Software releases 20.9 through 20.16
Cisco Catalyst SD-WAN Software releases 20.18
Cisco Catalyst SD-WAN Software releases 26.1
Recommendations
Users and administrators of affected products are advised to update to the latest versions immediately.
References
https://nvd.nist.gov/vuln/detail/CVE-2026-20303
https://nvd.nist.gov/vuln/detail/CVE-2026-20304
https://nvd.nist.gov/vuln/detail/CVE-2026-20310
